Object-Oriented Policy Configuration for Network Traffic Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As network devices provide increasingly complex functions, the complexity of their configuration increases, leading to potential performance decreases, network errors, application incompatibilities, and security weaknesses, particularly due to the need for managing complex policies and undefined policy scenarios.

Innovation Solution

The development of systems and methods for configuring and evaluating object-oriented policies that allow users to specify structured policy expressions for network traffic, enabling efficient processing of complex data streams and controlling policy execution orders, with provisions for handling undefined policy elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number and complexity of network device functions grow to provide more capabilities, then the functionality and versatility of the network device improve, but the configuration complexity and administrative overhead increase

Engineering Contradiction:
ImprovefunctionalityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the policy configuration into multiple hierarchical levels including policy groups, policy banks, and individual policies. This segmentation allows administrators to organize complex policies into manageable units that can be independently configured and reused across different network functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal policy templates and expressions that can be applied across multiple network device functions and traffic types. A single policy expression can serve multiple purposes through parameterization, reducing the need to create separate configurations for similar functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If more policies are added to handle increased network device functions, then the policy coverage and control capability improve, but the processing overhead and configuration time increase

Engineering Contradiction:
Improvepolicy coverageVSAvoidconfiguration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent enables administrators to pre-configure policy templates, expressions, and group hierarchies before they are needed. These pre-configured elements can be quickly instantiated and modified for specific scenarios, eliminating the need to create policies from scratch each time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a nested hierarchy where policies are organized within policy groups, which are contained within policy banks. This nested structure allows administrators to work at different levels of abstraction, configuring general policies at higher levels and specific instances at lower levels, reducing overall configuration effort.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Manufacturing precision

If complex policy expressions are used to analyze HTTP traffic content, then the policy precision and traffic control accuracy improve, but the processing speed and performance decrease

Engineering Contradiction:
Improvetraffic control accuracyVSAvoidprocessing speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent replaces traditional pattern-matching and string-analysis mechanisms with object-oriented expression evaluation. This substitution allows for more efficient processing by using structured data comparison and parameter matching instead of character-by-character analysis of HTTP traffic.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms complex policy conditions into parameterized expressions that can be efficiently evaluated. By changing the representation from raw traffic analysis to structured parameter comparison, the system achieves both high precision and improved processing speed.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If the policy framework is made more flexible to handle undefined policy scenarios, then the adaptability and completeness of policy handling improve, but the system complexity increases

Engineering Contradiction:
Improvepolicy handling completenessVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces policy banks as an intermediary layer between the policy engine and the actual policy execution. This intermediary provides a default policy mechanism that handles undefined scenarios without requiring complex modifications to the core policy evaluation logic, maintaining system simplicity while improving completeness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9450837B2Systems and methods for configuring policy bank invocations
Publication Date: 2016.09.20 CITRIX SYSTEMS INC
  • US9450837B2 patent drawing
  • US9450837B2 patent drawing
  • US9450837B2 patent drawing

AI summary

Systems and methods for configuring and evaluating policies that direct processing of one or more data streams are described. A configuration interface is described for allowing users to specify object oriented policies. These object oriented policies may allow any data structures to be applied with respect to a payload of a received packet stream, including any portions of HTTP traffic. A configuration interface may also allow the user to control the order in which policies and policy groups are executed, in addition to specifying actions to be taken if one or more policies are undefined. Systems and methods for processing the policies may allow efficient processing of object-oriented policies by applying potentially complex data structures to unstructured data streams. A device may also interpret and process a number of flow control commands and policy group invocation statements to determine an order of execution among a number of policies and policy groups. These policy configurations and processing may allow configuration and processing of complex network behaviors relating to load balancing, VPNs, SSL offloading, content switching, application security, acceleration, and caching.